---
id: CVE-2026-104445
title: >-
  YesWiki before 4.6.7 contains an authentication bypass vulnerability in the
  ActivityPub inbox that fails to bind the verified HTTP signature signer to the
  activity actor
summary: >-
  YesWiki before 4.6.7 contains an authentication bypass vulnerability in the
  ActivityPub inbox that fails to bind the verified HTTP signature signer to the
  activity actor. Unauthenticated attackers with any ActivityPub keypair can
  send si…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L'
cwe:
  - CWE-290
vendor: YesWiki
product: yeswiki
affected:
  - yeswiki < 4.6.7
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T12:17:15.770'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104445'
references:
  - url: 'https://github.com/YesWiki/yeswiki/security/advisories/GHSA-rm6r-grfg-4v78'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/yeswiki-before-4.6.7-authentication-bypass-via-activitypub-inbox-actor-spoofing
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-02T12:17:44.338Z'
---

## Overview

YesWiki before 4.6.7 contains an authentication bypass vulnerability in the ActivityPub inbox that fails to bind the verified HTTP signature signer to the activity actor. Unauthenticated attackers with any ActivityPub keypair can send signed Delete or Update activities referencing a mirrored entry's sourceUrl to delete or overwrite other actors' federated entries.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
